PT-2025-20336 · Linux+3 · Linux Kernel+3

Vlad Poenaru

·

Published

2025-05-08

·

Updated

2026-05-26

·

CVE-2025-37807

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the Linux kernel, specifically in the bpf (Berkeley Packet Filter) module. The issue arises due to the non-8-byte aligned storage of percpu pointers in the htab elem set ptr() function. This causes the kmemleak detector to fail to identify the memory leak, resulting in an unreferenced object. The problem can be reproduced using the bpf selftest by enabling the CONFIG DEBUG KMEMLEAK config, adding a getchar() before skel destroy in test hash map(), and running the test progs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-62729
AZL-69938
BDU:2025-10756
CVE-2025-37807
ECHO-3FB9-56F3-7815
OESA-2025-1539
OESA-2025-1540
USN-7594-1
USN-7594-2
USN-7594-3

Affected Products

Astra Linux
Debian
Linux Kernel
Ubuntu